| CVE ID | CVE-2026-82928 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Inclusion of Undocumented Features or Chicken Bits (CWE-1242) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82929 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Use of Hard-coded Cryptographic Key (CWE-321) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82930 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Missing Authentication for Critical Function (CWE-306) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82932 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Improper Restriction of Communication Channel to Intended Endpoints (CWE-923) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82933 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Reliance on HTTP instead of HTTPS (CWE-1428) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82935 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | - Use of Unmaintained Third Party Components (CWE-1104) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-82936 |
| Publication date | 28 September 2026 |
| Vendor | F&F Filipowski |
| Product | mH-DEVELOPER |
| Vulnerable versions | All before 3.0.30 |
| Vulnerability type (CWE) | Allocation of Resources Without Limits or Throttling (CWE-770) |
| Report source | Report to CERT Polska |
Description
During its own research, Krzysztof Chudzik from CERT Polska discovered vulnerabilities in F&F Filipowski mH-DEVELOPER devices. Research was conducted using the GLM 5.2 LLM, the findings were manually verified and consulted with the vendor. The CERT.PL team has coordinated the disclosure of said vulnerabilities.
The vulnerability CVE-2026-82928: mH-DEVELOPER smart home module contains a hardcoded SSH public key in /root/.ssh/authorized_keys, serving as a potential backdoor. The SSH daemon allows root login via key authentication and starts automatically. An attacker with the matching private key can gain a root shell on any affected device, resulting in full system compromise. The key cannot be removed without remounting the file system and survives a factory reset. Vendor notes that this functionality was used only for service purposes.
The vulnerability CVE-2026-82929: mH-DEVELOPER smart home module uses the same hard-coded SSH host keys on every device, with no per-device key generation. An attacker who extracts these keys from the firmware can set up a rogue SSH server that clients will trust without warning, enabling man-in-the-middle attacks and credential interception.
The vulnerability CVE-2026-82930: mH-DEVELOPER smart home module does not verify tokens in its authorization middleware, leaving all HTTP API and WebSocket endpoints accessible without authentication. An unauthenticated attacker on the LAN can query these endpoints, access system information, and send raw control commands to manipulate building automation devices.
The vulnerability CVE-2026-82932: mH-DEVELOPER smart home module does not load any firewall rules at startup. This leaves all listening services, including SSH, HTTP, WebSocket, and Node-RED, fully exposed on the LAN without access control. Any client on the same network can reach every service.
The vulnerability CVE-2026-82933: mH-DEVELOPER smart home module sends its web interface and API traffic over unencrypted HTTP. Passwords, authentication tokens, and device commands are transmitted in cleartext. An attacker on the same network can intercept this traffic, steal credentials and tokens, and hijack sessions.
The vulnerability CVE-2026-82935: mH-DEVELOPER smart home module ships with an end-of-life, unsupported Debian 8 and Node.js runtime v17.0.1 in its production firmware. This exposes the device to publicly known vulnerabilities that will not receive security patches. An attacker could exploit these known flaws to execute arbitrary code, access sensitive data, or cause a denial of service on the device.
The vulnerability CVE-2026-82936: mH-DEVELOPER smart home module is vulnerable to Denial of Service due to uncontrolled resource consumption. The Express bodyParser is configured with a 250 MB limit for JSON and URL-encoded request bodies. An authenticated attacker on the LAN can send large request bodies that exhausts buffers in RAM, causing out-of-memory conditions and crashing the fh-node process, resulting in denial of service. The successful attack depends on the current memory usage of the device which is not under full control of the attacker. Critically, due to CVE-2026-82930 all endpoints can be queried unauthenticated, so any user on LAN can perform this attack.
These issues were fixed in version 3.0.30
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.